CVE-2024-1485 - CVE House
Back to Database
Status published High CVE-2024-1485

Registry-support: decompress can delete files outside scope via relative paths

Vulnerability Description

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1485

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Joern Schneeweisz (GitLab Security Research Team) for reporting this issue.

Affected Vendor

Affected Software

OpenShift Developer Tools and Services, Red Hat OpenShift Container Platform 4
Vulnerable Versions:
1.16.2

Timeline

Official Publish: February 13th, 2024
Last Modified: March 24th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H

Weaknesses (CWE)